Carta Trust Center | Powered by Conveyor

Carta

Quick Summary

One or more annual third-party audit(s)

Has a formal mobile device management (MDM) program

Annual third-party penetration testing

Has a disaster recovery plan

Subprocessors list available

Has cyber insurance

Has a bug bounty or vulnerability disclosure program

Deletes customer data on request

Has an API available

Uses a centralized IAM solution (SSO) to manage employee access

Has a status page

Has a privacy policy

Has an AI policy

Compliance

ISO 27001:2022

SOC 2 Type II

SOC 1 Type II

SIG

GDPR

CCPA

Featured Documents

Carta's Password Policy

Carta's Business Continuity Plan (External)

Carta SIG Core 2026

Carta ISO 27001 Certification

Carta ISO 27001 Certificate 2025-2028

Carta ISO 27001 - SOA v1.0 - March 2025

Bridge Letter for Carta's 2025 SOC 2 Reports

Avantia (now Carta Law) ISO 27001 Certification

2025 SOC 2 Type 2 Report for Capdesk

2025 SOC 2 Type 2 for ListAlpha (now CRM)

2025 SOC 2 Type 2 - Avantia Law (now Carta Law)

2025 SOC 1 Type 2 Report for Money Movement

2025 SOC 1 Type 1 Report for Money Movement

2025 Carta Audit Confirmations Service SOC 1 Type 1 Report

Use of AI at CARTA

Accelex (now LPPA) ISO 27001 Certification

2025 SOC 2 Type 2 for Sirvatus (now Loan Ops)

2025 Pen Test - Executive Report

2025 Carta Audit Confirmations Service SOC 1 Type 1 Report

2025 SOC 2 Type 2 Report for Carta Platform

2025 SOC 1 Type 2 Report for Fund Administration

2025 SOC 1 Type 2 Report for Cap Table

2025 SOC 1 Type 2 Report for Money Movement

2025 SOC 1 Type 2 Report for Fund Services

2025 SOC 1 Type 2 Report for Financial Reporting

Bridge Letter for Carta's 2025 SOC 1 Reports

Carta Data Processing Addendum

Documents & Knowledge Base FAQs

Documents27